Skip to content

Start a transaction signing flow with TOTP

Request

Start a transaction signing flow with TOTP. Receive a challenge to add to the authenticator app.

Security
ClientAccessToken
Bodyapplication/jsonrequired
device_idstring, <= 80 characters

Identifier of the device from which the authentication request originates

approval_dataobjectrequired

Flat object that contains the data that your customer should approve for a transaction signing or custom approval flow. It can contain up to 10 keys, and only alphanumeric characters, underscores, hyphens, and periods. It will be returned as a claim in the ID token upon successful authentication.

Example:
{ "transaction_id": "eFII2y40uB9hQ98nXt3tc1IHkRt8GrRZiqZuRn_59wT", "sum": "200" }
identifier_typestringrequired

Type of user identifier used for login

identifierstringrequired

User identifier, which may correspond to the user's email, phone number, username, or user ID. The type of identifier should be specified as the identifier_type.

curl -i -X POST \
  https://api.sbx.transmitsecurity.io/cis/v1/auth/totp/transaction/start \
  -H 'Authorization: Bearer <YOUR_TOKEN_HERE>' \
  -H 'Content-Type: application/json' \
  -d '{
    "device_id": "string",
    "approval_data": {
      "transaction_id": "eFII2y40uB9hQ98nXt3tc1IHkRt8GrRZiqZuRn_59wT",
      "sum": "200"
    },
    "identifier_type": "string",
    "identifier": "string"
  }'

Responses

Backend auth initialized successfully.

Bodyapplication/json
approval_dataobjectread-onlyrequired

Approval data object.

Example:
{ "transaction_id": "eFII2y40uB9hQ98nXt3tc1IHkRt8GrRZiqZuRn_59wT", "sum": "200" }
challengestringread-onlyrequired

Totp transaction challenge

Example:"123456"
Response
{ "approval_data": { "transaction_id": "eFII2y40uB9hQ98nXt3tc1IHkRt8GrRZiqZuRn_59wT", "sum": "200" }, "challenge": "123456" }